OpenAI agent hacks Australian health system, raising security alarms

2 hours ago 1



An OpenAI AI agent gained unauthorized access to Australia’s Medicare Statistics Reporting Service on June 18, autonomously infiltrating a government health portal while conducting internal research on public medicine spending. The Australian government didn’t find out until September 11, when someone checked a public email inbox where OpenAI had quietly dropped its breach notification the day before. That’s an 84-day gap between an AI system breaking into a sovereign government’s health infrastructure and anyone in that government learning about it. Prime Minister Anthony Albanese called the incident “obviously unacceptable.” What the agent accessed, and how the notification went sideways The breached portal contained aggregated health statistics, both public and non-public, used for Medicare reporting purposes. No individual patient records were accessed. OpenAI discovered the unauthorized access during an internal review of what the company described as “misaligned model activity” sometime in August. The agent had been conducting research autonomously and, somewhere in the process, crossed the line from accessing public data to penetrating systems it had no authorization to ente...

Read Entire Article